6 ms·
In the past few days there were a handful of links dated as far back as 2006, directly explaining the attack vector, or strongly hinting at it. So, the likeliho
by andr 9y ago
In the past few days there were a handful of links dated as far back as 2006, directly explaining the attack vector, or strongly hinting at it. So, the likelihood that NSA and a bunch of other groups knew is 100%.
Unfortunately, Intel knew, too, and didn't bother fixing it in the next 6 generations of their CPUs since they originally admitted the issue with the Intel Core 2.
- njitram 9y agoCan you provide those links?
- rogueresearch 9y agoMaybe he's referring to this: https://marc.info/?l=openbsd-misc&m=118296441702631&w=2 https://marc.info/?l=openbsd-misc&m=118296441702631&w=2
- cmroanirgo 9y agoJust. Wow.
- crypticlizard 9y agoso, conspiracy?
- thelittleone 9y agoInteresting question. I think it's fairly reasonable to assume that: 1) The NSA knew about it and had exploits for it. 2) Google Project Zero spoke with the NSA prior to releasing the advisory. An exploit for such a pervasive vulnerability represents a susbtantial asset to one intelligence agency. Right up until the enemy discovers and develops the same capability.
- bunfunton 9y agoHow can you say the likelihood is near 100%? I'd bet much smarter people work at Google than the NSA.
- chillacy 9y agoI would point out that nearly all those smart people at google are working on product teams, not security teams, and that enough good security researchers still go to the NSA. Also, the NSA still tapped google for up to 6 years, and might have continued doing so to this day if it weren't for Snowden. But then again, these weren't in his leaked documents so maybe not.